const isAdmin = (req, res, next) => {
  if (!req.user.isAdmin) {
    res.status(401).json({ success: false, message: '无权限访问' });
  } else {
    next();
  }
};

module.exports = isAdmin;
